Request is an http client. If a request is made using ```multipart```, and the body type is a ```number```, then the specified number of non-zero memory is passed in the body. This affects Request >=2.2.6 <2.47.0 || >2.51.0 <=2.67.0.
The code transmits data to another actor, but a portion of the data includes sensitive information that should not be accessible to that actor.
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
Link | Tags |
---|---|
https://github.com/request/request/pull/2018 | issue tracking exploit third party advisory |
https://nodesecurity.io/advisories/309 | third party advisory exploit |
https://github.com/request/request/issues/1904 | issue tracking exploit third party advisory |